Observed Signal · Aug 6, 2026 · Guilty Plea · Source: techcrunch · Impact: 4/5 · Sentiment: Negative

Hacker Pleads Guilty in Snowflake Customer Data Theft

Executive Signal Summary

Connor Moucka, a 26-year-old Canadian, pleaded guilty to hacking more than 165 Snowflake customers, stealing billions of records and extorting affected companies and individuals, the U.S. Department of Justice said. Prosecutors say Moucka and co-conspirators received over $2.5 million in ransom payments and about $500,000 from selling stolen data on hacking forums; victims suffered approximately $9.5 million in losses. Targets included major customers such as AT&T, LendingTree and Ticketmaster, with more than 100 million AT&T customers’ call and text records reportedly accessed. Moucka was arrested in Canada in late 2024, faces decades in prison and is scheduled for sentencing on October 27, 2026.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

Large-scale criminal compromise of a major cloud data warehouse (Snowflake) affecting many enterprise customers and hundreds of millions of records; has material implications for cloud security, data governance, incident response, and customer trust across industries.

SIGNAL RADAR

Track Snowflake Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • Connor Moucka pleaded guilty to hacking more than 165 Snowflake customers, according to the U.S. Department of Justice.
  • Moucka and his co-conspirators stole billions of records and extorted multiple companies and individuals.
  • They received more than $2.5 million in ransom payments and about $500,000 from selling victims’ data on hacking forums.
  • Victims suffered approximately $9.5 million in losses, per the DOJ.
  • Targets included AT&T (over 100 million customers’ call and text records), LendingTree, and Ticketmaster.

Connected Companies & Entities

5 Entities mapped

“Moucka was accused of hacking cloud provider Snowflake, which allowed him and his co-conspirators to break into dozens of the company’s cust...”

“including AT&T, LendingTree, and Ticketmaster. Moucka stole data from more than 100 million AT&T customers, including call and texting recor...”

“Austin Larsen, a senior researcher at Google’s cybersecurity firm Mandiant who had been investigating the Snowflake hacks......”

Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: techcrunch•Published: Aug 6, 2026
Original Coverage Title: “Hacker pleads guilty to stealing data from more than 165 Snowflake customers”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

SecurityFeb 25, 2026

Defense Contractor Sentenced for Selling Hacking Tools to Russia

Peter Williams, a 39-year-old Australian and former general manager of Trenchant at U.S. defense contractor L3Harris, pleaded guilty and was sentenced to 87 months in prison for stealing and selling his company’s hacking and surveillance tools to a Russian exploit broker known as Operation Zero. Prosecutors say Williams sold the tools for about $1.3 million in cryptocurrency between 2022 and 2025. The U.S. Treasury sanctioned Operation Zero and its founder Sergey Zelenyuk, and L3Harris estimated a $35 million loss related to the theft. The specific zero-day exploits taken have not been publicly disclosed, and questions remain about which products were affected, whether affected vendors were notified, and how a separate employee was scapegoated during the internal investigation.

Read assessment
CybersecurityFeb 24, 2026

Ex-L3Harris Exec Jailed for Selling Hacking Tools to Russia

Peter Williams, a former general manager of Trenchant (a division of defense contractor L3Harris), was sentenced to seven years in prison after pleading guilty to stealing and selling his former company’s hacking and surveillance tools to a Russian broker. U.S. prosecutors said Williams sold seven Trenchant trade secrets to the broker Operation Zero, and the U.S. Treasury Department announced sanctions against Operation Zero. The Department of Justice stated the tools could have allowed access to millions of devices worldwide. Williams, a 39-year-old Australian living in Washington, D.C., admitted he received approximately $1.3 million in cryptocurrency from sales made between 2022 and 2025. Initial reporting on the sentencing was published by Bloomberg and Cyberscoop; TechCrunch reported the case summary and related announcements.

Read assessment
Cybersecurity / MalwareJul 23, 2026

Steam fake games infected 8,000 PCs; FBI arrests suspect

Between May 2024 and February 2026, cybercriminals published seven fake games on Valve's Steam platform that concealed malware designed to harvest credentials and other sensitive data to access cryptocurrency wallets. The campaign infected nearly 8,000 PCs and allowed attackers to empty roughly 80 wallets, stealing about $220,000. The operators promoted the malicious titles via social media and bots to target high-value crypto holders; victims included Twitch streamer RastalandTV, who lost $32,000 and later died in March 2026. The FBI, working with affected gamers, traced stolen funds through Bitrefill vouchers and arrested a 21-year-old suspect in Florida. Authorities say the accused bought a Remote-Access Trojan for about $10,000 and faces charges including conspiracy to distribute malware, which carries potential prison terms of roughly 5–20 years.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.